CVE-2025-24689

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 27, 2025
CWE ID 538

Summary

CVE-2025-24689 is a vulnerability affecting the Import and export users and customers functionality in codecs, where sensitive information can be inserted into externally-accessible files or directories. This issue allows an attacker to retrieve embedded sensitive data, potentially leading to data breaches or unauthorized access. The vulnerability impacts versions from n/a through 1.27.12. Organizations using these affected versions should prioritize updating to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share